Certified Ethical Hacker v11 312-50v11 – Question185

A friend of yours tells you that he downloaded and executed a file that was sent to him by a coworker. Since the file did nothing when executed, he asks you for help because he suspects that he may have installed a trojan on his computer.
What tests would you perform to determine whether his computer is infected?

A.
Upload the file to VirusTotal.
B. You do not check; rather, you immediately restore a previous snapshot of the operating system.
C. Use ExifTool and check for malicious content.
D. Use netstat and check for outgoing connections to strange IP addresses or domains.

Correct Answer: A